Why It Matters
Competing federal cybersecurity rules are making it harder for critical infrastructure operators to respond to cyber threats, according to a new GAO report published Sept. 28. Industry panelists, speaking at a discussion convened by the U.S. Government Accountability Office (GAO), said that where federal cybersecurity regulations are duplicative or conflicting, it could be difficult to fully satisfy all reporting requirements while remediating cyber threats. The panel included representatives from three sectors, energy, financial services, and healthcare and public health, which the Government Accountability Office identified as subject to a significant number of cybersecurity regulations.
The Big Picture
Critical infrastructure is mostly owned by the private sector, and federal agencies have issued numerous regulations to help protect health data and ensure the smooth operation of financial systems, among other things. The Office of the National Cyber Director has noted that when critical infrastructure sectors are subject to multiple cybersecurity regulations, the result can be conflicting guidance, inconsistencies, increased compliance costs, and redundancies for regulated entities. The Government Accountability Office's High Risk list calls for a national cybersecurity strategy.
Panelists specifically flagged the Department of Homeland Security's proposed rule for cyber incident reporting and the Securities and Exchange Commission's cybersecurity disclosure rules as duplicative or in conflict with their own sector-specific regulations. Representatives from all three sectors said that while some progress in harmonizing federal cybersecurity regulations had been made over the prior year, including increased regulatory guidance for financial institutions, half of the participants considered that progress limited.
Participants proposed two remedies: consistent reporting timeframes and thresholds, which they said could streamline requirements and reduce duplication, and a lead agency to coordinate and receive incident reports, which they said would increase collaboration between government agencies and industry.
The participants included chief and senior executives overseeing cybersecurity, medical, and industry operations, as well as regulatory affairs and legal specialists.
The Bottom Line
The Department of Homeland Security and the Securities and Exchange Commission are the agencies most directly named in connection with the duplicative rules that panelists identified, and both would likely figure in any harmonization effort going forward.
Tracking whether Congress or the administration moves to designate a lead coordinating agency or standardize incident-reporting thresholds is possible through Legis1.
A linked invitation to track related legislative activity on Legis1
Access the Legis1 platform for comprehensive political news, data, and insights.
Spot something wrong? Report an issue with this article